Exhedria · 2026-10-10-draft-2

Exhedria Privacy Policy

Review draft 2 — October 10, 2026. Not effective or approved for publication. This describes the intended soft-launch service, including AI-assisted search once activated. Provider activation and hosted checks remain pending. Bracketed items must be resolved before publication; see REVIEW_NOTES.md.

Effective date: [SET AT PUBLICATION]

Who is responsible

[FULL LEGAL OPERATOR NAME], operating as Exhedria, is responsible for the practices described here. This policy covers exhedria.com and its member service. Contact support@exhedria.com about privacy questions or requests. [Confirm whether applicable law requires an additional business mailing contact; a personal home address is not proposed.]

Information we collect

We receive information directly from you, from members who invite or interact with you, from our authentication provider and from operation of the service:

An inviter can supply your name, email address and an assessment of their relationship with you before you join. Receiving an invitation does not itself make you a member. Contact us if you want us to review or remove information associated with an unwanted invitation.

Why we use information

We use information to verify eligibility and invitation access; create and maintain accounts; display profiles to their chosen audience; calculate network reach and relationship tiers; provide search, connections, introductions and conversations; deliver requested service communications; enforce contact permissions and abuse restrictions; provide support; and measure, maintain and improve the service.

We may group or standardize supplied company, role, industry and similar terms to improve discovery and administration. A standardized category is not an independently verified fact about a person or company. We do not create and persist new profile facts inferred from private conversations.

What other members can see

Whole-profile audiences are all platform members or your connected network. These are member audiences, not a public internet directory. Visibility remains subject to current access and blocking rules. Birthday and career-update sharing have separate choices and remain subject to profile visibility. An enabled birthday appears in the day’s Relationships birthday area; your date of birth is not displayed on your profile.

Messages are available to their permitted conversation participants under the applicable conversation rules. Introduction participants receive information necessary for their role; a visible path does not give every intermediary access to the final-recipient message. We do not describe messages as end-to-end encrypted.

Your individual assessment inputs are not public profile fields. The product displays a shared relationship tier and can disclose your assessment tier to the other person after that person starts scoring the relationship. The weaker assessment determines the retained shared tier. Do not treat a relationship assessment as completely confidential from the person being assessed.

Changing an audience or blocking someone affects future access under the service’s rules. It cannot recall information already seen, copied or lawfully received by another person. Shared group history and archived conversations have their own participation rules.

AI-assisted search

When you use enabled AI-assisted search, we send the search objective and selected, permitted profile evidence to OpenAI to help assess relevance. The evidence is restricted to profile information the searching member is authorized to access. Results are checked against current access before display.

Credentials, member email addresses, dates of birth, private messages, private relationship assessments, behavior reports and internal settings are excluded from other members’ AI profile evidence. However, if you type sensitive information into your own search prompt, that text may be transmitted as part of the prompt. Please do not include it.

AI does not grant contact permission, determine introduction eligibility or send a request for you. An audience change after a request has already been transmitted cannot recall that transmission. Provider retention and use must be understood separately from Exhedria’s own records.

OpenAI’s API data policy states that API data is not used to train or improve its models unless the customer explicitly opts in. Exhedria will not opt in to sharing member data for that purpose. This is separate from storage: OpenAI’s default abuse-monitoring logs may contain prompts and responses and may be retained for up to 30 days, with longer retention where required by law or reasonably necessary to protect its services or others from harm. We do not claim zero data retention.

Our current search integration sends Responses API requests with storage disabled (store: false). That setting does not disable abuse-monitoring retention. [BEFORE ACTIVATION: verify the production organization/project has no training/data-sharing opt-in and confirm the deployed endpoint/configuration still matches this description. No member data has been sent by preparing this policy.]

Providers and other disclosures

The planned launch providers are Clerk for authentication/account services, Render for application and database hosting, Resend for invitation/service email, OpenAI for enabled AI search, and Google Workspace for support email. Each receives information relevant to the service it provides. [CONFIRM THE FINAL ACTIVE PROVIDER LIST, CONTRACTS, LOCATIONS AND LINKS BEFORE PUBLICATION.]

Authorized personnel may access information when needed to operate the service, answer support requests, investigate abuse or meet legal obligations. Routine administrative screens limit access and do not display private message bodies, credential secrets or individual assessment inputs. This is not a claim that privileged infrastructure access is technically impossible.

We may disclose information when legally required or reasonably necessary to protect people, investigate misuse or defend legal rights. In a business transfer, information may transfer subject to applicable law and appropriate notice/protections.

We do not sell personal information or share it for cross-context behavioral advertising. We do not authorize our providers to use member information for those purposes. [PRELAUNCH CHECK: verify provider contracts/settings support this confirmed commitment.]

Cookies, storage and tracking choices

The service and its authentication provider use session/security technologies needed for sign-in and safe operation. Browser storage may also support preferences and service state. Blocking essential technologies can prevent sign-in or normal use.

[PUBLICATION CHECK: inventory deployed cookies/storage, purposes, providers and durations, including authentication scripts. Specify whether any optional analytics or third-party cross-site tracking occurs, how any consent/opt-out is handled, and the actual response to Do Not Track and Global Privacy Control signals. Do not state that such signals are honored until implementation is verified.]

Retention and deletion

We retain information according to the purpose it serves, account status, safety needs and legal requirements. Certain product measurement records are scheduled for deletion after 400 days; this does not mean all account information or messages are deleted after 400 days. Email invitations remain pending until used under the current product rules, rather than expiring like connection requests.

Account deletion removes or replaces identifying profile information and specified member-associated records in the service. It can leave a minimal deletion marker and altered conversation records needed to preserve other participants’ history and prevent an old recovery copy from restoring the account. Provider account deletion and backup expiration are separate processes. Copies held by other members are outside our control.

[PUBLICATION REQUIREMENT: approve and verify a category-specific retention schedule for pending invitations, messages, support mail, operational/audit records, provider logs and backups. Specify deletion completion expectations and any legally required retention. Do not promise immediate removal from all systems or indefinite retention without a documented purpose.]

Your choices and requests

Use available profile and account controls to review or change information and visibility choices. Contact support@exhedria.com to request access, correction, deletion or help with your information, including information supplied by an inviter. We may ask for information reasonably needed to verify the request; do not send passwords or identity documents unless a secure, necessary process is arranged.

Depending on where you live and which laws apply, you may have additional rights, including receiving a copy of information, objecting to certain uses or appealing a request decision. We will respond under applicable law and explain applicable limitations. [LEGAL REVIEW: determine required state-specific disclosures, appeal methods and request processes; do not claim every law or exemption applies.]

Security, location and children

We use access controls and other safeguards to protect information, but no service can guarantee absolute security. Contact support@exhedria.com if you suspect an account or privacy incident. This mailbox is not an emergency or continuously staffed service.

Exhedria is intended for adults aged 18 or older meeting the service’s United States current-location requirement. It is not intended for children. Contact us if you believe a child has provided information so we can investigate and take appropriate action.

[PUBLICATION CHECK: specify actual processing locations and any necessary international-transfer disclosures after confirming provider arrangements. A United States launch does not by itself prove all processing stays in the United States.]

Changes and contact

We will post the effective date of policy changes and provide appropriate notice of material changes. Where required, we will seek consent for a new use rather than applying this policy retroactively. Questions and requests: support@exhedria.com. [Add a non-home business mailing contact if required following the address review.]